Microsoft Publisher Bug in Processing Object Header Data Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1020015 |
|
SecurityTracker URL: http://securitytracker.com/id/1020015
|
|
CVE Reference:
CVE-2008-0119
(Links to External Site)
|
Date: May 13 2008
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2000 SP3, 2002 SP3, 2003 SP3, 2007 SP1; and prior service packs
|
Description:
A vulnerability was reported in Microsoft Publisher. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a Publisher file with specially crafted object header data that, when loaded by the target user, will trigger a memory error and execute arbitrary code on the target system. The code will run with the privileges of the target user.
Cocoruder of Fortinet Security Research reported this vulnerability.
|
Impact:
A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution:
The vendor has issued the following fixes:
Microsoft Publisher 2000 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=8675b9b6-fbf0-4ad2-9210-285e2cc10556
Microsoft Publisher 2002 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=df623784-6e26-42c0-9e21-e7960b849e1e
Microsoft Publisher 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=c18b060b-9828-4952-8e80-5328c0832d83
Microsoft Publisher 2003 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=c18b060b-9828-4952-8e80-5328c0832d83
Microsoft Publisher 2007:
http://www.microsoft.com/downloads/details.aspx?FamilyId=e4b647c2-79a3-49e0-9b1d-741667fdbcca
Microsoft Publisher 2007 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=e4b647c2-79a3-49e0-9b1d-741667fdbcca
A restart is not required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-027.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms08-027.mspx (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 13 May 2008 13:19:17 -0400
Subject: Microsoft Security Bulletin MS08-027 Critical: Vulnerability in Microsoft Publisher Could Allow Remote Code Execution (951208)
|
http://www.microsoft.com/technet/security/bulletin/ms08-027.mspx
CVE-2008-0119
|
|